| GR-PO-SEC-C-Windows10 ENT Applocker Full Control | |
| Data collected on: 2-9-2025 09:49:52 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5-adm |
| Created | 30-9-2020 12:56:56 |
| Modified | 8-4-2025 14:31:08 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 215 (AD), 215 (SYSVOL) |
| Unique ID | {dffff58f-b54c-4b65-9a46-58a137552256} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | Yes | Enabled | emea.tpg.ads/GR/Systems/Clients |
| Name |
|---|
| EMEA\GR-L-SEC-Windows Enterprise FULL Applocker Control |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\GR-L-SEC-Windows Enterprise FULL Applocker Control | Read (from Security Filtering) | No |
| EMEA\tentolouris.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | MSTeams, from Microsoft | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Cortana Allowed | Microsoft.Windows.Cortana, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-G-ORG-USERS Accounting | Signed by * | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MicrosoftSway | Microsoft.Office.Sway, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\GR-L-SEC-Restricted Search on Start menu | Microsoft.Windows.CloudExperienceHost, from Email, phone, or Skype | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps ScreenRecorderProWin10 Allowed | 57506winuwp.ScreenRecorderProForWin10, from winuwp | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Win Experience Pack Allowed | MicrosoftWindows.Client.CBS, from Microsoft Windows | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Microsoft.Paint Allowed | Microsoft.Paint, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.PeopleExperienceHost, from Microsoft Corporation | Publisher | No |
| Allow | BUILTIN\Administrators | Signed by * | Publisher | No |
| Allow | Everyone | MicrosoftWindows.Client.CBS, from Microsoft Windows | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MicrosoftToDo Allowed | Microsoft.Todos, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MSAccountsControl Allowed | Microsoft.Windows.CloudExperienceHost, from Email, phone, or Skype | Publisher | No |
| Allow | EMEA\GR-G-ORG-Remote Admin Users | Signed by * | Publisher | No |
| Allow | Everyone | Microsoft.Windows.StartMenuExperienceHost, from ms-resource:StartMenuExperienceHost/PublisherDisplayName | Publisher | No |
| Allow | Everyone | windows.immersivecontrolpanel, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.Apprep.ChxApp, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.ShellExperienceHost, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Facebook Sups QA Baseline Restrictions | Microsoft.MicrosoftEdge.Stable, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps OneNote Allowed | Microsoft.Office.OneNote, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Microsoft Copilot Allowed | Microsoft.Copilot, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\GR-L-SEC-Restricted Search on Start menu | Microsoft.Windows.ContentDeliveryManager, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps WinOTP Authenticator Allowed | 34135VladimirAkopyan.WinOTPAuthenticator, from Vladimir Akopyan | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Snip & Sketch Allowed | Microsoft.ScreenSketch, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Photos Allowed | Microsoft.Windows.Photos, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps DesktopAppInstaller | Microsoft.DesktopAppInstaller, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Xbox Game Bar Allowed | Microsoft.XboxGamingOverlay, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.WindowsCalculator, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\GR-L-SEC-Restricted Search on Start menu | Microsoft.Windows.Search, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Search Allowed | Microsoft.Windows.Search, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps WindowsCommunicationApps | microsoft.windowscommunicationsapps, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Sticky Notes Allowed | Microsoft.MicrosoftStickyNotes, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-G-ORG-IT-Systems-ADM | Signed by * | Publisher | No |
| Allow | Everyone | Windows.PrintDialog, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Camera Allowed | Microsoft.WindowsCamera, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps 3DPaint Allowed | Microsoft.MSPaint, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MSAccountsControl Allowed | Microsoft.AccountsControl, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.WindowsStore, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps PDF Reader Kdan Mobile Allowed | 0D9A1B2D.PDFReaderUWP, from Kdan Mobile Software Ltd. | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Groove Music Allowed | Microsoft.ZuneMusic, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps OneDrive Allowed | microsoft.microsoftskydrive, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Trello Allowed | 45273LiamForsyth.PawsforTrello, from Trello, Inc. | Publisher | No |
| Allow | Everyone | InputApp, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Whiteboard Allowed | Microsoft.Whiteboard, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-G-ORG-IT | Signed by * | Publisher | No |
| Allow | NT AUTHORITY\SYSTEM | Signed by * | Publisher | No |
| Allow | Everyone | Microsoft.LockApp, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.AAD.BrokerPlugin, from Assigned by your organization | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MicrosoftSmartCardManager | Microsoft.MicrosoftSmartCardManager, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps WhatsApp Allowed | 5319275A.WhatsAppDesktop, from WhatsApp Inc. | Publisher | No |
| Allow | Everyone | WavesAudio.MaxxAudioProforDell2019, from Waves Audio | Publisher | No |
| Allow | Everyone | Microsoft.MicrosoftEdge, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps Calculator Allowed | Microsoft.WindowsCalculator, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Facebook Sups QA Baseline Restrictions | Microsoft.MicrosoftEdge, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MSNotepad Allowed | Microsoft.WindowsNotepad, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\GR-L-SEC-Apps MobilePASS Allowed | 05EB1CFA.SafeNetMobilePASS, from Gemalto Pte Ltd | Publisher | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\GR-L-SEC-AppsRestrict WordPad Notepad | WORDPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | MICROSOFT TEAMS UPDATE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Facebook Sups QA Baseline Restrictions | IEXPLORE.EXE, in INTERNET EXPLORER, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\GR-L-SEC-AppsRestrict WordPad Notepad | NOTEPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | MICROSOFT TEAMS, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Facebook Sups QA Baseline Restrictions | TEAMS.EXE, in MICROSOFT TEAMS, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Facebook Sups QA Baseline Restrictions | UPDATE.EXE, in MICROSOFT TEAMS UPDATE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Facebook Sups QA Baseline Restrictions | MSEDGE.EXE, in MICROSOFT EDGE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS Supervisors Baseline Restrictions V2 | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS Trainers Baseline Restrictions | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS QA Baseline Restrictions | * | Path | Yes |
| Deny | EMEA\tentolouris.5-test | tentolouris.5-test test | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS QA Baseline Restrictions V2 | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS ALL Restrict Mgmt Access | Restricted Access for MGMT | Path | Yes |
| Allow | Everyone | (Default Rule) All files located in the Program Files folder | Path | No |
| Deny | EMEA\GR-L-SEC-AppsRestrict SnippingTool | %SYSTEM32%\SnippingTool.exe | Path | No |
| Allow | Everyone | (Default Rule) All files located in the Windows folder | Path | No |
| Deny | EMEA\GR-L-SEC-AppsRestrict CMD&Powershell | %SYSTEM32%\WindowsPowerShell\v1.0\powershell_ise.exe | Path | No |
| Deny | EMEA\GR-G-ORG-USERS Stihl Agents | Deny Stihl Agents | Path | Yes |
| Allow | Everyone | * | Path | No |
| Deny | EMEA\GR-L-SEC-AppsRestrict CMD&Powershell | %SYSTEM32%\WindowsPowerShell\v1.0\powershell.exe | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All files | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | (Default Rule) All digitally signed Windows Installer files | Publisher | No |
| Deny | EMEA\GR-G-ORG-USERS ALL Restrict Mgmt Access | Restricted Access for MGMT | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS Supervisors Baseline Restrictions V2 | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS QA Baseline Restrictions V2 | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS Stihl Agents | Stihl Agents | Path | Yes |
| Allow | Everyone | (Default Rule) All Windows Installer files in %systemdrive%\Windows\Installer | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All Windows Installer files | Path | No |
| Allow | Everyone | Allow All | Path | No |
| Deny | EMEA\GR-G-ORG-USERS Trainers Baseline Restrictions | * | Path | Yes |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | (Default Rule) All scripts located in the Program Files folder | Path | No |
| Deny | EMEA\GR-G-ORG-USERS Supervisors Baseline Restrictions V2 | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS Stihl Agents | Stihl Agents | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS Trainers Baseline Restrictions | * | Path | Yes |
| Deny | EMEA\GR-G-ORG-USERS ALL Restrict Mgmt Access | Restricted Access for MGMT | Path | Yes |
| Allow | Everyone | (Default Rule) All scripts located in the Windows folder | Path | No |
| Allow | Everyone | Allow All | Path | No |
| Deny | EMEA\GR-G-ORG-USERS QA Baseline Restrictions V2 | * | Path | Yes |
| Allow | BUILTIN\Administrators | (Default Rule) All scripts | Path | No |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Specify settings for optional component installation and component repair | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off the Store application | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not connect to any Windows Update Internet locations | Disabled |